Close Menu
New York Examiner News

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    DJ Screw’s Catalog Is Coming to Streaming for the First Time

    May 31, 2026

    This viral recruiter says Gen Z isn’t lazy. Corporate America is just mad they’re harder to manipulate

    May 31, 2026

    Padres’ Fernando Tatis Jr snaps 207 at-bat home run drought vs Nats

    May 31, 2026
    Facebook X (Twitter) Instagram
    New York Examiner News
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    New York Examiner News
    Home»Technology»An AWS Configuration Issue Could Expose Thousands of Web Apps
    Technology

    An AWS Configuration Issue Could Expose Thousands of Web Apps

    By August 21, 2024
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    An AWS Configuration Issue Could Expose Thousands of Web Apps


    A vulnerability related to Amazon Web Service’s traffic-routing service known as Application Load Balancer could have been exploited by an attacker to bypass access controls and compromise web applications, according to new research. The flaw stems from a customer implementation issue, meaning it isn’t caused by a software bug. Instead, the exposure was introduced by the way AWS users set up authentication with Application Load Balancer.

    Implementation issues are a crucial component of cloud security in the same way that the contents of an armored safe aren’t protected if the door is left ajar. Researchers from the security firm Miggo found that, depending on how Application Load Balancer authentication was set up, an attacker could potentially manipulate its handoff to a third-party corporate authentication service to access the target web application and view or exfiltrate data.

    The researchers say that looking at publicly reachable web applications, they have identified more than 15,000 that appear to have vulnerable configurations. AWS disputes this estimate, though, and says that “a small fraction of a percent of AWS customers have applications potentially misconfigured in this way, significantly fewer than the researchers’ estimate.” The company also says that it has contacted each customer on its shorter list to recommend a more secure implementation. AWS does not have access or visibility into its clients’ cloud environments, though, so any exact number is just an estimate.

    The Miggo researchers say they came across the problem while working with a client. This “was discovered in real-life production environments,” Miggo CEO Daniel Shechter says. “We observed a weird behavior in a customer system—the validation process seemed like it was only being done partially, like there was something missing. This really shows how deep the interdependencies go between the customer and the vendor.”

    To exploit the implementation issue, an attacker would set up an AWS account and an Application Load Balancer, and then sign their own authentication token as usual. Next, the attacker would make configuration changes so it would appear their target’s authentication service issued the token. Then the attacker would have AWS sign the token as if it had legitimately originated from the target’s system and use it to access the target application. The attack must specifically target a misconfigured application that is publicly accessible or that the attacker already has access to, but would allow them to escalate their privileges in the system.

    Amazon Web Services says that the company does not view token forging as a vulnerability in Application Load Balancer because it is essentially an expected outcome of choosing to configure authentication in a particular way. But after the Miggo researchers first disclosed their findings to AWS at the beginning of April, the company made two documentation changes geared at updating their implementation recommendations for Application Load Balancer authentication. One, from May 1, included guidance to add validation before Application Load Balancer will sign tokens. And on July 19, the company also added an explicit recommendation that users set their systems to receive traffic from only their own Application Load Balancer using a feature called “security groups.”



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleEurope’s JUICE Jupiter Probe Zooms past the Moon in Historic Flyby
    Next Article Harris energizes crowd in surprise virtual DNC appearance while campaigning in key swing state

    RELATED POSTS

    SoftBank says it will invest up to €75 billion to build French data centers

    May 31, 2026

    ‘Backrooms’ Takes You Deeper Inside the Internet’s Most Uncanny Horror Myth

    May 31, 2026

    Founders seize on Indian court ruling to revive criticism of Google’s ad business

    May 30, 2026

    24 Best Father’s Day Gifts for Dads (2026)

    May 30, 2026

    This chip startup just raised $135M on a bet that AI’s biggest bottleneck isn’t compute — it’s memory

    May 29, 2026

    The GOP’s Attacks on James Talarico Are Straight Out of the Incel Handbook

    May 29, 2026
    latest posts

    DJ Screw’s Catalog Is Coming to Streaming for the First Time

    DJ Screw’s catalog is finally making it to streaming platforms this month. Starting today with…

    This viral recruiter says Gen Z isn’t lazy. Corporate America is just mad they’re harder to manipulate

    May 31, 2026

    Padres’ Fernando Tatis Jr snaps 207 at-bat home run drought vs Nats

    May 31, 2026

    SoftBank says it will invest up to €75 billion to build French data centers

    May 31, 2026

    How Turkey Hacked the Hair Transplant Industry

    May 31, 2026

    Jason Blum on Obsession, Backrooms Box Office Success Saving Our Industry

    May 31, 2026

    9 of TV’s Hottest Dance Scenes, Ranked

    May 31, 2026
    Categories
    • Books (1,276)
    • Business (6,180)
    • Events (55)
    • Film (6,117)
    • Lifestyle (4,214)
    • Music (6,235)
    • Politics (6,174)
    • Science (5,534)
    • Technology (6,113)
    • Television (5,800)
    • Uncategorized (7)
    • US News (6,168)
    popular posts

    Gwen Stefani and Blake Shelton reveal ‘precious’ new addition to family

    Gwen Stefani and Blake Shelton introduced fans to their newest kitten, Corn. Pic credit: ©ImageCollect.com/AdMedia…

    How a Cup of Tea Laid the Foundations for Modern Statistical Analysis

    March 26, 2025

    US Coast Guard Report on Titan Submersible Implosion Singles Out OceanGate CEO Stockton Rush

    August 6, 2025

    Here’s Why You Stop Liking Someone When They Like You Back

    July 3, 2023
    Archives
    Browse By Category
    • Books (1,276)
    • Business (6,180)
    • Events (55)
    • Film (6,117)
    • Lifestyle (4,214)
    • Music (6,235)
    • Politics (6,174)
    • Science (5,534)
    • Technology (6,113)
    • Television (5,800)
    • Uncategorized (7)
    • US News (6,168)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Jason Blum on Obsession, Backrooms Box Office Success Saving Our Industry

    May 31, 2026

    9 of TV’s Hottest Dance Scenes, Ranked

    May 31, 2026

    What a Nutritionist Wants You to Know

    May 31, 2026
    © 2026 New York Examiner News. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT